Browser fingerprinting library with the highest accuracy and stability
88%
Total Score
healthy
Active, established package with strong provenance and maintenance; workflow actions are all unpinned and no security policy is published.
The package uses a prepare lifecycle script, which adds install-time behavior and warrants awareness, but this signal alone does not indicate an unsafe or unhealthy release.
The repository has no published security policy, leaving vulnerability-reporting expectations unclear. This is a transparency gap, partially offset by CodeQL and Snyk usage.
All 17 analyzed action references are unpinned, creating avoidable workflow reproducibility and action-substitution risk. No untrusted checkouts, script injection, high-severity findings, or incomplete audit files were reported; one workflow also has top-level write permissions, but no untrusted trigger reaches it.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.